# T1650 Acquire Access

> As of 2026-10-05, T1650 (Acquire Access) appears in 25 tracked threats, first reported 2026-04-10 and most recently 2026-10-04, with linked actors including Everest, TheHatman, APT43; it most often appears alongside T1078 (Valid Accounts).

- **Tracked threats:** 25 (1 critical, 15 high, 6 medium, 1 low)
- **First seen:** 2026-04-10
- **Last seen:** 2026-10-04
- **Threat actors:** 11
- **Detection rules:** 18 (counts only; Blue tier and above)

## Key facts

- **ID:** T1650
- **Framework:** MITRE ATT&CK
- **Tactics:** Resource Development
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1650/

## Activity timeline

T1650 first appeared in tracked threats on 2026-04-10 and was most recently reported on 2026-10-04. The busiest month was 2026-07 with 8 reports, and 25 of the 25 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1650 Acquire Access is catalogued by MITRE ATT&CK under the Resource Development tactic in the Enterprise matrix. Threadlinqs maps 25 of 2623 tracked threats (1%) to it; by severity that is 1 critical, 15 high, 6 medium, 1 low.

Threats that use T1650 most often also use [T1078 Valid Accounts](https://intel.threadlinqs.com/technique/T1078) (16 threats), [T1657 Financial Theft](https://intel.threadlinqs.com/technique/T1657) (16 threats), [T1213 Data from Information Repositories](https://intel.threadlinqs.com/technique/T1213) (13 threats), [T1567 Exfiltration Over Web Service](https://intel.threadlinqs.com/technique/T1567) (13 threats), [T1566 Phishing](https://intel.threadlinqs.com/technique/T1566) (10 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

11 tracked threat actors appear in the threats that use T1650; the most frequent are [Everest](https://intel.threadlinqs.com/actor/Everest) (2), [TheHatman](https://intel.threadlinqs.com/actor/TheHatman) (2), [APT43](https://intel.threadlinqs.com/actor/APT43) (1), [Coinbase Cartel](https://intel.threadlinqs.com/actor/Coinbase%20Cartel) (1), [CoinbaseCartel](https://intel.threadlinqs.com/actor/CoinbaseCartel) (1).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1650.

- [M1056 Pre-compromise](https://attack.mitre.org/mitigations/M1056/)

## Threat actors using it

- [Everest](https://intel.threadlinqs.com/actor/Everest) — 2
- [TheHatman](https://intel.threadlinqs.com/actor/TheHatman) — 2
- [APT43](https://intel.threadlinqs.com/actor/APT43) — 1
- [Coinbase Cartel](https://intel.threadlinqs.com/actor/Coinbase%20Cartel) — 1
- [CoinbaseCartel](https://intel.threadlinqs.com/actor/CoinbaseCartel) — 1
- [Kimsuky](https://intel.threadlinqs.com/actor/Kimsuky) — 1
- [SHADOWBYT3$](https://intel.threadlinqs.com/actor/SHADOWBYT3%24) — 1
- [Safepay](https://intel.threadlinqs.com/actor/Safepay) — 1
- [Scattered LAPSUS$ Hunters](https://intel.threadlinqs.com/actor/Scattered%20LAPSUS%24%20Hunters) — 1
- [Storm-2755](https://intel.threadlinqs.com/actor/Storm-2755) — 1
- [UNC5537](https://intel.threadlinqs.com/actor/UNC5537) — 1

## Tracked threats

25 tracked threats use T1650.

- [Snowflake customer-account extortion campaign (UNC5537): Canadian suspect Connor Riley Moucka pleads guilty](https://intel.threadlinqs.com/threat/TL-2026-2908) — high — 2026-10-04
- [Insiders for Hire: Underground Market for Employee Access Expands Beyond Privileged IT Roles](https://intel.threadlinqs.com/threat/TL-2026-2799) — medium — 2026-09-30
- [Infostealers Target Corporate AI Accounts, Sessions and API Keys (LLMjacking Risk)](https://intel.threadlinqs.com/threat/TL-2026-2752) — high — 2026-09-28
- [Iran Exploits SS7 Cellular Interconnect Infrastructure to Track US Military Personnel](https://intel.threadlinqs.com/threat/TL-2026-2609) — high — 2026-09-21
- [Illegal IPL Betting Platform Network: 1,200+ Domains, Deepfake Celebrity Endorsements, and Systematic…](https://intel.threadlinqs.com/threat/TL-2026-2126) — high — 2026-08-23
- [Threat Actor 'TheHatman' Claims Theft of 3.6M+ Azure/Entra Tenant Employee Records from McDonald's, Gap…](https://intel.threadlinqs.com/threat/TL-2026-2047) — medium — 2026-08-17
- ["TheHatman" Azure/Entra Directory Exfiltration Campaign Exposes Millions of Employee Records at McDonald's…](https://intel.threadlinqs.com/threat/TL-2026-2027) — high — 2026-08-16
- [ModernStealer: Cross-Platform Dark Web/Telegram Broker Network Claims Sale of Government and Defense Data](https://intel.threadlinqs.com/threat/TL-2026-1836) — medium — 2026-08-03
- [Alleged Żabka Polska Breach: 541K Jira Issues, 230K IT Tickets, 89 GitLab Repos, and…](https://intel.threadlinqs.com/threat/TL-2026-1834) — high — 2026-08-03
- [SplitVPN (formerly NotVPN) Breach Exposes 58M Connection Logs, 23.4M User Records Despite 'No Logs' Claims](https://intel.threadlinqs.com/threat/TL-2026-1815) — high — 2026-07-29
- [SafePay Ransomware Abuses OneDrive Sync Client for Covert Data Exfiltration](https://intel.threadlinqs.com/threat/TL-2026-1728) — high — 2026-07-27
- [Sextortion Scammers Impersonate ShinyHunters, Exploit Leaked Breach Data for Bitcoin Extortion](https://intel.threadlinqs.com/threat/TL-2026-1722) — low — 2026-07-27
- [Everest Ransomware Gang Extorts Stadler Rail via Compromised Supplier Credentials, CHF 10M Demand Refused](https://intel.threadlinqs.com/threat/TL-2026-1683) — medium — 2026-07-25
- [Chick-fil-A Confirms Data Breach After Credential Stuffing Attack Exposes Customer Personal and Payment Data](https://intel.threadlinqs.com/threat/TL-2026-1654) — high — 2026-07-23
- [ReHub: Russian-Language Cybercrime Marketplace Sponsoring DragonForce, LockBit, CHAOS, Anubis, The…](https://intel.threadlinqs.com/threat/TL-2026-1594) — medium — 2026-07-21
- [Ransomware Attack Halts Fairlife (Coca-Cola Subsidiary) US Dairy Production Operations](https://intel.threadlinqs.com/threat/TL-2026-1456) — high — 2026-07-17
- [Threat Actors Mass-Probe Gitea Docker Deployments for CVE-2026-20896 Authentication Bypass Amid Exploitarium…](https://intel.threadlinqs.com/threat/TL-2026-1136) — critical — 2026-07-06
- ["Total Access to All Your Devices" Sextortion Email Extortion Campaign](https://intel.threadlinqs.com/threat/TL-2026-0934) — medium — 2026-06-24
- [Dark Web Identity-Theft Ecosystem: $0.95 Fullz, STORM Infostealer-as-a-Service, and Scam-as-a-Service…](https://intel.threadlinqs.com/threat/TL-2026-0919) — high — 2026-06-23
- [Anthropic claude.ai Shared-Chat Feature Abused in ClickFix Malvertising Campaign Delivering MacSync macOS…](https://intel.threadlinqs.com/threat/TL-2026-0856) — high — 2026-06-18
- [Ransomware Double-Claiming: Why the Same Victim Appears on Two Leak Sites](https://intel.threadlinqs.com/threat/TL-2026-2248) — 2026-06-17
- [Duplicate Ransomware Leak-Site Claims: RaaS Cartels, Affiliate Re-Extortion, Access-Broker Resale, and…](https://intel.threadlinqs.com/threat/TL-2026-0843) — 2026-06-17
- [Dark Web Data-Leak Roundup (June 2026): Iran Hajj Organization (168M records), AdressFakta/SUPEReROI Sweden…](https://intel.threadlinqs.com/threat/TL-2026-0803) — high — 2026-06-15
- [Grafana Labs Source Code Theft via Stolen GitHub Access Token — CoinbaseCartel Extortion Campaign](https://intel.threadlinqs.com/threat/TL-2026-0527) — high — 2026-05-18
- [Storm-2755 'Payroll Pirate' Campaign: AiTM Phishing and Workday Account Hijacking Targeting Canadian…](https://intel.threadlinqs.com/threat/TL-2026-0346) — high — 2026-04-10

## Related CVEs

CVEs referenced by the tracked threats that use T1650, most frequent first.

- [CVE-2025-27152](https://intel.threadlinqs.com/cve/CVE-2025-27152)
- [CVE-2026-20896](https://intel.threadlinqs.com/cve/CVE-2026-20896)
- [CVE-2026-22874](https://intel.threadlinqs.com/cve/CVE-2026-22874)
- [CVE-2026-25038](https://intel.threadlinqs.com/cve/CVE-2026-25038)
- [CVE-2026-27771](https://intel.threadlinqs.com/cve/CVE-2026-27771)
- [CVE-2026-27775](https://intel.threadlinqs.com/cve/CVE-2026-27775)
- [CVE-2026-58053](https://intel.threadlinqs.com/cve/CVE-2026-58053)

## Detection coverage

Threadlinqs maintains 18 detection rules mapped to T1650 (SPL 7, KQL 5, Sigma 6). Rule content is available to Blue tier accounts and above; this page shows counts only.

18 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1650
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
